SB20250226734 - Resource management error in Linux kernel net dsa driver
Published: February 26, 2025 Updated: May 11, 2025
Security Bulletin ID
SB20250226734
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2022-49654)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the qca8k_port_change_mtu() function in drivers/net/dsa/qca8k.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/188c798f3c2554fa0d7147e9b97baf144b817019
- https://git.kernel.org/stable/c/1993f5a06736ada59dd54b50dc96755a38796ee5
- https://git.kernel.org/stable/c/386228c694bf1e7a7688e44412cb33500b0ac585
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.54
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.18.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19